Live data from Hacker News

Ubuntu Security Updates Are a Confusing Mess

gld.mcphail.uk

31–40 of 40 posts

Re: Ubuntu Security Updates Are a Confusing Mess

#31

Earlier quoted context omitted.

> The build of systemd and firewalld on 18.04 are both categorically broken. Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu? If it was acceptable at the time, then it's not a reason to rush off onto a new release where something else might be categorically broken. Even if it sucks, you already figured out how to deal with…

> Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu? They were and still are. The irony: the fix need not be breaking/demand a new major release. > Most server code is not going to get very out of date over the course of several years. It's not significantly more decrepit than the day it was deployed. That's my point. It was…

> That's my point. It was broken from the beginning.

They already put it into production though, so that's not very relevant to deciding when they move off of it.

You have a valid complaint, I just don't think it has much to do with service life.

Re: Ubuntu Security Updates Are a Confusing Mess

#32

Earlier quoted context omitted.

> Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu? They were and still are. The irony: the fix need not be breaking/demand a new major release. > Most server code is not going to get very out of date over the course of several years. It's not significantly more decrepit than the day it was deployed. That's my point. It was…

> That's my point. It was broken from the beginning. They already put it into production though, so that's not very relevant to deciding when they move off of it. You have a valid complaint, I just don't think it has much to do with service life.

> They already put it into production though, so that's not very relevant to deciding when they move off of it.

It's one of those "if a tree falls in the woods" scenarios, though. It's not a default-install package.

People who selected it already dealt with it or keep running into it. Changing the backend won't even affect them; config edits are preserved.

To add (one final poor point): they're a tiny minority! This production is like... nothing.

Fixing it/changing course/introducing 'breakage' (a correction) is less adversarial than leaving it broken IMO.

There were several ways to approach this, some more user visible than others...

The 'proper' thing, changing the backend, would've been felt. Patching the errant argument use was also entirely an option. They even had several actual LTS' to do this in!

The 'service life', like the cake, is a lie. While we debate best practices - they fail to execute them!

I appreciate you putting up with my rambling though

Re: Ubuntu Security Updates Are a Confusing Mess

#33
Most Ubuntu users don't know that Canonical only supports the main repository for free.

To my knowledge, only some comments hidden in /etc/apt/sources.list mention this, but the more honest approach would be to warn all users when they try to `apt install foo` some package from universe/multiverse. Or do it like RHEL with their EPEL repo and disable it by default.

But I guess they would have never gotten this popular if people saw that Ubuntu is only a few thousand packages compared to Debian's tens of thousands.

Re: Ubuntu Security Updates Are a Confusing Mess

#34
post #6

Ubuntu is reselling Debian, once they made it well, now I don't know

I'm hard-pressed to name a feature that Ubuntu has that isn't part of Debian. But it's what people like, so I package for Ubuntu :/

Debian packages also work for Ubuntu, no?

Re: Ubuntu Security Updates Are a Confusing Mess

#35
post #34

Earlier quoted context omitted.

I'm hard-pressed to name a feature that Ubuntu has that isn't part of Debian. But it's what people like, so I package for Ubuntu :/

Debian packages also work for Ubuntu, no?

not really, some libraries might have different ABI

Re: Ubuntu Security Updates Are a Confusing Mess

#36

> ...what are my options? > ...Maybe it is time to go back to Debian, as they seem to release these fixes to their users? Curious if this would actually be a solution. They state that fixes in Debian are down-streamed regardless of support, so if this fix wasn't down-streamed, then why would it be in Debian ?

The fix is in debian (and in devian derivatives like devuan) https://security-tracker.debian.org/tracker/CVE-2022-42252

As for why it isn't in Ubuntu 22.04 - perhaps because the Ubuntu release schedule does not match debian's. Debian buster was released in september 2022 - Ubuntu's April tagging is probably based off of the prior debian release which only gets critical updates.

Re: Ubuntu Security Updates Are a Confusing Mess

#38

Your free personal Ubuntu Pro subscription does in fact cover as many VMs and containers as you can run on up to five personal machines, as the OP well knows. I like that we make Ubuntu Pro, including universe updates, free for anyone running at small scale.

Thanks for the reply and the correction. I've updated the post to reflect this. I'm sure it will be helpful for others, as the UI doesn't reflect that these containers do not come out of the overall allocation. As you'll see in the screenshot I've added, it looks as if these are being counted as 8 physical machines against 5 tokens.

Re: Ubuntu Security Updates Are a Confusing Mess

#39
post #6

Ubuntu is reselling Debian, once they made it well, now I don't know

I'm hard-pressed to name a feature that Ubuntu has that isn't part of Debian. But it's what people like, so I package for Ubuntu :/

It used to be that Ubuntu had more resources to test against various laptop hardware. These days, it's much easier to buy hardware that just works with any kernel.

Unless you intend to pay for support, I see no reason to not prefer Debian in 2024.

Re: Ubuntu Security Updates Are a Confusing Mess

#40
The updates in universe are definitely best effort.

We were paying for Ubuntu Pro through an AWS subscription on 2k EC2 instances, and could not get Canonical to update a package with a CVSS 7.8 in the 18.04 LTS.

We've moved off Ubuntu Pro as a result. Blogged it at https://blog.thinkst.com/2024/07/unobtrusively-upgrading-ubu...

Post reply on HN